Download Print this page

Communication States; Required Open Ports; General Issues And Solutions - Cisco MARS Install And Setup Manual

Advertisement

Appendix B
Troubleshooting

Communication States

When troubleshooting the communications, first verify that the Local Controller and Global Controller
are communicating properly. From the web interface of the Global Controller, view the device state on
the Admin > System Setup > Local Controller Information page. Understanding the communication
state can assist you in diagnosing issues.
The key states to check for when troubleshooting communications issues are as follows:
Note
For a complete list of states and their meanings, see
Controller Page, page

Required Open Ports

When a Global Controller and Local Controller are separated by a firewall, open the following ports on
both the inside and outside interfaces of the firewall to ensure proper operation of the Global Controller:
TCP Port
22
443
8444

General Issues and Solutions

The following symptoms and solutions address many synchronization errors.
Deleting and re-adding a Local Controller is rarely, if ever, the solution. This change also causes a
Tip
full re-synchronization of topology data, resulting in an even longer downtime (possibly days). You
should only delete a Local Controller if you want to permanently remove that Local Controller from
the Global Controller.
OL-14672-01
Active. This state indicates that communications are operational. If you made a recent change, wait
a minute for the system to process the change and then re-visit the page to obtain the updated state.
After adding a new Local Controller, the page briefly indicates the Active state even though you
have not added the certificates. Re-visit the page to obtain the correct state.
Certificate Errors. This state indicates the certificates are not configured correctly. If this state
appears, validate the certificates on both the Local Controller and Global Controller. See
the Security Certificates, page 2-10
Synchronizing (progress). This state results from triggering a full topology synchronization. A
status indicator allows you to monitor the progress.
2-5.
Troubleshooting Global Controller-to-Local Controller Communications
Table 2-3Local Controller Status Messages on Zone
Function
Secure Shell (SSH) used by Local Controller for
topology and device discovery
Hyper Text Transport Protocol with Secure
Sockets Layer (HTTPS) use for user interface
access
Cisco Proprietary data synchronization between a
Global Controller and Local Controllers.
Install and Setup Guide for Cisco Security MARS
Importing
B-7

Advertisement

loading